A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
The failure is happening after the local device saves the passkey, but before Microsoft Entra ID completes registration. In this flow, the most relevant supported causes are cross-device requirements, stale/orphaned passkeys, and registration interruptions.
Recommended checks:
- Verify cross-device prerequisites
- For the QR-based phone flow, Bluetooth must be enabled on both the Windows device and the mobile device.
- Both devices must be in range and connected to the internet.
- If the organization restricts Bluetooth, cross-device passkey authentication can fail.
- Avoid registration interruptions
- The documented user flow completes only after identity verification, naming the passkey, and selecting Done on the Passkey created screen.
- If the process times out or a step is not completed before the device times out, registration can fail at the end.
- Private browsing can also cause the final save to fail; the error shown in the screenshot is consistent with that possibility.
- Clean up stale or orphaned passkeys before retrying
- An orphaned passkey can exist when the passkey remains on the device but is no longer registered with Microsoft Entra ID.
- Remove the failed/orphaned passkey from the device or passkey provider first.
- Then retry registration so a fresh passkey is created and registered.
- If users changed PIN or biometric setup on the phone
- A passkey can become invalid if the authentication method on the device changed, such as PIN or biometric changes.
- In that case, set up a new passkey and remove old passkeys that no longer apply.
- Check platform support level
- Older Windows, macOS, mobile OS, and browser versions might not fully support passkeys.
- If this is occurring broadly, confirm affected users are on supported, current OS and browser versions.
- If using Authenticator passkeys with attestation enforced
- Registration can fail if Apple or Google attestation services are heavily loaded or unavailable.
- Cross-device registration flows do not support registration of attested passkeys.
- If attestation is required in the passkey profile, test direct registration in the Authenticator app rather than cross-device QR registration.
- For tenant-side investigation
- Review audit logs and sign-in logs for the affected registration attempts.
- Microsoft guidance for account recovery scenarios also states that passkey registration failures should be evaluated through audit logs.
A practical retry sequence is:
- Delete the failed passkey from the mobile device/passkey provider.
- Ensure Bluetooth is on for both devices and both have internet access.
- Retry in a normal browser session, not private/incognito.
- Complete the flow without delay through the final Done step.
- If the tenant enforces attestation, test direct Authenticator app registration instead of the QR cross-device flow.
- If it still fails, inspect Entra audit/sign-in logs for the registration event.
References: